PT-2018-11228 · Ntop+1 · Ntopng+1

Ioannis Profetis

·

Publicado

2018-07-05

·

Atualizado

2024-02-10

·

CVE-2018-12520

CVSS v3.1

8.1

Alta

VetorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ntopng versions prior to 3.4.180617
Description An issue was discovered where the pseudo-random number generator (PRNG) involved in generating session IDs is not seeded at program startup, resulting in deterministic session IDs for active user sessions. This allows an attacker with knowledge of the operating system, standard library, and target username to hijack a user's session and escalate their access.
Recommendations For versions prior to 3.4.180617, update to version 3.4.180617 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive areas of the application to minimize the risk of session hijacking.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-12520
USN-4842-1

Produtos afetados

Ubuntu
Ntopng